![]()
Sygnia, the foremost global cyber readiness and response team, released the findings of their investigation into ongoing activity by a China-nexus threat actor, targeting key infrastructure that routes, authenticates, connects, and manages high-value environments. Tracked by Sygnia as ‘Fire Ant’, the adversary leveraged novel attack tools and methods to target Cisco IOS XR routers and turn them into operational platforms that suppress evidence of threat actor activity, collect traffic and credentials, and enable Fire Ant to explore other access points with the goal of spreading to other organizations.
This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260830433829/en/
The threat actor reaches BridgeAgent on the legacy Linux server, where a GRE tunnel provides a pivot to the edge router and opens a route into a connected environment.
The 2026 findings represent an evolution of Fire Ant’s activity, expanding their focus beyond their 2025 activity of deep persistence within virtualization infrastructure targeting VMware ESXi and vCenter environments to strategic infrastructure abuse.
“Fire Ant didn’t just compromise systems. It compromised the trust layer those systems depend on. The routers, authentication servers, and management infrastructure many organizations overlook as legacy technology became the attacker’s vantage point for reach, visibility, and control,” said Asaf Perlman, Director of Incident Response at Sygnia. “That is what makes this research so important: the significance extended beyond the initially compromised environment, as the affected infrastructure could provide a path toward other connected high-value environments.”
Key findings of the threat report include:
- ‘Target behind the target’ – 2026 activity compromised both direct and connected high-value environments, targeting infrastructure that other systems depend on to communicate and be administered. Router infrastructure was exploited for covert connectivity and traffic collection to expand the threat actor’s reach to connected high-value environments.
- Authentication chokepoints – The threat actor compromised TACACS infrastructure to intercept administrative authentication flows, collect credentials, and weaken confidence in administrative audit trails.
- New attack tools – Sygnia’s investigation uncovered two novel tools. A masquerading implant tracked by Sygnia as BridgeAgent that is configured for tunnelling and persistence through a zabbix_agent.service systemd unit, set to run as root with automatic restart behavior and a TACACS credential-collection toolset tracked as TacTap that enabled library injection, accepted-session interception, and Unix-socket file-descriptor handoff.
- Resilient persistence – Fire Ant established a resilient access layer through long-lived implants across Linux management infrastructure, including Medusa-related components, custom SSH backdoors, Zabbix-masquerading malware, and packet-triggered backdoors.
- Defense evasion and evidence manipulation – The actor also manipulated the evidence layer by hiding logs, hiding commit activity, suppressing AAA requests, suppressing SNMP traps and filtering command output. On Linux systems, the actor deleted files after execution, left processes running from deleted paths, disabled SELinux, tampered with logs and modified firewall rules.
The new intelligence value from Sygnia’s investigation highlights a campaign targeting a highly interconnected environment where routers, TACACS servers and Linux management hosts were used as part of a broader access and collection layer. Fire Ant’s interest in the compromised organization should be understood not only as an attempt to compromise a single environment, but as an effort to control infrastructure that may enable visibility, collection, and potential access beyond the immediate victim.
Learn more about Fire Ant’s 2026 activity in the latest threat research, “Fire Ant Evolves: From Hypervisors to Trusted Infrastructure.”
About Sygnia
Sygnia is the world’s foremost incident response and cyber readiness team. It applies creative approaches and bold solutions to each phase of an organization’s security journey, meeting them where they are to ensure cyber resilience. Sygnia is the trusted advisor and service provider of leading organizations worldwide, including Fortune 100 companies. Sygnia is a Temasek company, part of the ISTARI Collective.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260830433829/en/
Media gallery
